一.MUX VLAN的由来
为了隔离用户,为不同的用户分配不同的VLAN,这样会导致使用大量的VLAN。而使用MUX VLAN可以利用其特性,节约一部分VLAN资源,且实现相同的效果。
如:现在网络中有3个用户组,A,B,C。要求A能与B,C互访;B可以与A互访,不能与C互访,且内部可以互访;C只能与A互访内部不能互访。用传统的VLAN也可以实现这个功能,但需要为用户组C内的所有用户分配一个VLAN来实现组内隔离,浪费VLAN。使用MUX VLAN可以将用户组划分到隔离型VLAN中实现相同的功能。
二.MUX VLAN描述
MUX VLAN由主VLAN和从VLAN构成,从VLAN又分为了隔离型VLAN和互通型VLAN。
从VLAN要与主VLAN绑定,一个主VLAN中最多设置一个隔离型从VLAN,可以设置多个互通型VLAN。
主VLAN可以和所有VLAN进行通信,内部也可以通信;互通型VLAN可以和主VLAN通信,内部也可以通信;隔离型VLAN可以和主VLAN通信,内部不同通信(当跨越交换机时,与另外一个交换机上的相同隔离型VLAN可以通信)
三.MUX VLAN对外访问的方式
(一)将交换机上连路由器的接口设置为主VLAN的接口。
SW1的配置:
[SW1]display current-configuration
#
sysname SW1
#
vlan batch 2 to 4
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
vlan 4
mux-vlan
subordinate separate 3
subordinate group 2
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 4
port mux-vlan enable
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 2
port mux-vlan enable
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 2
port mux-vlan enable
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 3
port mux-vlan enable
#
interface GigabitEthernet0/0/5
port link-type access
port default vlan 3
port mux-vlan enable
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
(二)通过VLAN聚合实现访问外网
SW2的代码:
[SW2]display current-configuration
#
sysname SW2
#
vlan batch 2 to 3 10
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
vlan 10
aggregate-vlan
access-vlan 2 to 3
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 192.168.1.254 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return